• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Crypto Whale Loses $6 Million in Phishing Scheme Through Malicious Signature Approval
Share
  • bitcoinBitcoin(BTC)$117,164.00
  • ethereumEthereum(ETH)$4,593.77
  • rippleXRP(XRP)$3.08
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$981.93
  • solanaSolana(SOL)$247.87
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.279020
  • staked-etherLido Staked Ether(STETH)$4,588.45
  • cardanoCardano(ADA)$0.93
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Crypto Whale Loses $6 Million in Phishing Scheme Through Malicious Signature Approval

News Desk
Last updated: September 18, 2025 10:24 pm
News Desk
Published: September 18, 2025
Share
crypto phishing

A significant incident in the crypto world has come to light, revealing the vulnerability of unsuspecting users to sophisticated phishing schemes. On September 18, a crypto whale suffered a staggering loss of over $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC). According to blockchain security firm Scam Sniffer, the incident was a result of the victim unknowingly approving malicious signatures.

The attackers executed a well-crafted scheme, disguising their actions as a routine wallet confirmation process through what is known as “Permit” signatures. This manipulation tricked the victim into approving fund transfers without raising any red flags. Yu Xian, the founder of the blockchain security company SlowMist, commented on the matter, explaining that the victim did not perceive any threat due to the absence of gas fees associated with the transaction. He emphasized the ease of the attack, stating, “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.”

Permit approvals were originally intended to enhance user experience by simplifying token transfers. Instead of conducting on-chain approvals that incur fees, users can sign off-chain messages that authorize spending. However, this efficiency has inadvertently opened a new avenue for malicious actors. Once a user grants such a permit, attackers can exploit the combination of two functions—Permit and TransferFrom—to siphon assets directly from the user’s wallet. Because the authorization is executed off-chain, wallet dashboards remain unaffected until the transaction is finalized on-chain, by which point the tokens have already been rerouted to the attacker’s wallet.

The recent incident underscores a growing trend in the realm of phishing, with Scam Sniffer reporting that in August alone, attackers accumulated $12.17 million from over 15,200 victims. This marked a significant 72% increase in losses compared to July. Notably, the losses were concentrated among a few large accounts, with three accounts accounting for nearly half of the total damages. One particularly striking case involved a wallet that lost $3.08 million in a single exploit.

The surge in phishing losses has been attributed to the rise of EIP-7702 batch-signature scams and direct transfers to malicious contracts. In light of this alarming trend, security experts are urging cryptocurrency users to exercise extreme caution when interacting with wallet requests. It is essential to be wary of any demands for unlimited permissions to wallets, as these can pave the way for significant financial losses.

The incident serves as a stark reminder of the ever-present risks in the digital asset landscape, highlighting the need for heightened security measures and user awareness to combat increasingly sophisticated phishing attacks.

Ethereum Price Predictions Lifted to $7,500 Amid Strong ETF Inflows and Staking Activity
Ethereum’s Complex Narrative Gains Momentum as Institutions Begin to Embrace DeFi
BTBT Fails to Secure Quorum for Ethereum Share Issuance Vote
Tom Lee: Ethereum Could Reach $62,000 If It Hits This ETH/BTC Ratio
Dogecoin Surges 40% Amid Growing Institutional Interest
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article In the center the title Solana Dogecoin Remi… Dogecoin and Solana Gain Attention as Remittix Emerges as a Utility-Driven Altcoin
Next Article ER7CT5KIDRFZFNN5YRSPXQIJ3I RCMP Claims Largest Crypto Bust in Canadian History, Seizing $56 Million from TradeOgre
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
a3d1e1d0 2057 11f0 9e3f a379ef0e0143
US Stock Futures Rise Ahead of Trump-Xi Call on Trade Negotiations
GettyImages 96522491 scaled
Thieves Steal $700,000 Worth of Rare Gold Samples from Paris Museum
75944396007 241030 fex ed ribbon cutting 11
Celebration of Life held for FedEx founder Fred Smith as company reports higher quarterly profits and forecasts 2026 earnings below estimates
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • Company
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Stocks
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?